PT-2026-60195 · Directus · Directus

CVE-2026-61836

·

Published

2026-07-15

·

Updated

2026-07-28

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 12.0.0
Description When response caching is enabled, the cache-key derivation process in the get-cache-key.ts file omits critical authorization context, including share, role, roles, admin, app, and policies. Because share tokens and anonymous requests may both be identified as user null, different shares or anonymous clients requesting the same URL and query may receive a cached response filtered for a different user's permissions without a new permission evaluation.
Recommendations Update to version 12.0.0.

Exploit

Fix

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61836
GHSA-C6W9-5G5J-JH2P

Affected Products

Directus